trust machine keyring (MoK) by default
authorLuca Boccassi <bluca@debian.org>
Mon, 30 Sep 2024 19:08:34 +0000 (21:08 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Mon, 30 Sep 2024 19:08:34 +0000 (21:08 +0200)
commita311d843d3bc67ab675f9650e6696bd0321296ef
tree061a5ea3ce4d9346bb546b09cdabad5daf423f05
parentf1fe2de3119bd41d85e453c858150027e3db7dc2
trust machine keyring (MoK) by default

Debian always trusted keys in MoK by default. Upstream made it conditional on
a new EFI variable being set. To keep backward compatibility skip this check.

Gbp-Pq: Topic features/all/db-mok-keyring
Gbp-Pq: Name trust-machine-keyring-by-default.patch
security/integrity/platform_certs/machine_keyring.c